Re: DOS Attack?

From: Mario Pascucci (ilpettegolo_at_yahoo.it)
Date: 11/25/04

  • Next message: Gethin Jones: "Re: which security hotfixs to implemet ?"
    To: security-basics@securityfocus.com
    Date: Thu, 25 Nov 2004 23:14:08 +0100
    
    

    Il gio, 2004-11-25 alle 03:22, Shawn Wall ha scritto:
    > Hi List,
    >
    > I'm currently experiencing network outages due to what appears to be DOS
    > attacks. I'm running a wireless ISP using a Cisco 2611 and CBAC and I have a
    > /24 public address range. During the outage I can see traffic from a single
    > external host sending thousands of packets to a single internal host. I
    > don't have port 80 inbound open in my ACLs so I don't understand how the
    > external host is even able to contact the internal host to begin with.
    > Secondly, how is it possible for an attack on 1 internal host to cripple the
    > rest of my network? Any feedback would be welcome. Thanks.

    Hi,
    consider that most worms (like Gaobot or SDbot or almost all *bot worms)
    uses connection from infected PC to attacker owned IRC server, to give
    control even if the PC is behind a firewall. Through this connection,
    the attacker can send "updates" to the viral code, or get data from the
    infected PC.
    If you can, check the kind of traffic and the TCP ports at the ends of
    the connection. Try to use a sniffer, if you can, to detect the type of
    connection and the direction of the traffic.
    HTH

    -- 
    Mario "Reliant" Pascucci
    http://ilpettegolo.altervista.org/
    

  • Next message: Gethin Jones: "Re: which security hotfixs to implemet ?"

    Relevant Pages

    • Re: [Full-disclosure] Packet sniffing help needed
      ... > Comp1= Windows xp box, Connected via dial up to a free ISP ... accessed a standard POP3 or FTP server over an insecure connection (i.e. ... The attacker doesn't really have to do anything ... But if the user dismisses this warning without ...
      (Full-Disclosure)
    • Re: wireless help
      ... With some Mac and ip list restrict to your user only, ... if the attacker as an ip and a mac but cant use any services ... the victim, the victim, is out, and the attacker can get is connection. ... be encryption like VPN or IPSec, I suspect. ...
      (Security-Basics)
    • Re: Surely an attacker cant *completely* hide his ip address?
      ... ]I have IPCop currently set up as a linux NAT firewall box but I want ... ]very difficult to track down an attacker. ... have proper log files to record the IP of the person who broke into his ... ]way he could disguise this first step without hijacking a connection ...
      (comp.os.linux.security)
    • Re: How secure is SSL emails?
      ... >source address but this time without source routing. ... Unless the attacker is able to convince V to interpret the attacker's ... second connection as a second connection, ... A TCP connection is defined by the 4-tuple of. ...
      (sci.crypt)
    • RE: Newbie Questions
      ... > I don't understand how an attacker can obtain IP addresses. ... They can get addresses from a whois / DNS route, or by block from ARIN, ... the very minimal protection obscuring your connection provides. ... > what about dial-up connections? ...
      (Security-Basics)